4 ms·
And you are right, too. But isolation doesn't mean translation. It is crazy that we have to use translation to overcome problems with IP space scarcity, but I
by NetStrikeForce 11y ago
And you are right, too.
But isolation doesn't mean translation. It is crazy that we have to use translation to overcome problems with IP space scarcity, but I guess we all got used already.
- themartorana 11y agoI don't know. I LIKE NAT. It's easy for me to reason about, easy to read and understand. I know it has a litany of shortcomings, and I'm not in a huge corporate network, but I'm going to miss it when it's gone.
- EvanAnderson 11y agoYou would like stateful packet filtering w/o NAT even more, I suspect. You've probably never gotten a chance to work in an environment where that's possible. It's nice to have one layer of complexity (NAT) removed from the equation and to work with only packet filters. (It's nice not to have to worry about split-horizon DNS, for example.)
- zAy0LfpBZLC8mAC 11y agoWhy would you miss it when it's gone? I pretty much wish it had never been invented, so I'd be curious if there is any big advantage that I am missing ...
- iigs 11y agoI also strongly like NAT. In roughly descending order: 1) It fails safe. Virtually all device misconfigurations result in failure to pass traffic, rather than being passed accidentally. 2) You get full control of your external signature (at that protocol level). When Comcast and AT&T realize that they can charge for more than a single /128 on their consumer networks we'll see a lot of wailing and gnashing of teeth on /r/technology, and it will be completely inane to those of us that saw the same companies attempt the same BS with NAT detection in the late 90s. 3) I would like to be able to implement dual stack in networks that I'm responsible for with as much similarity as possible. Having to reason independently more than needed about how IPv4 and IPv6 behave is needless difficulty. 4) IPv6 allocations today are asininely large. We're going to have 30-45 years of overallocation and then be out again, and in the interim we'll have a whole host of new braindead protocols in the manner of FTP and VOIP. The collective lessons we've learned about NAT will have (for all intents and purposes) been lost and we'll get a bunch of new shoddy hacks for dealing with them (passive FTP and NAT-T). 5) If it's a useful tool, by the user's estimation, why can't I have it? The internet grew up on what amounted to "be a good peer and we can all get along", but on this specific topic it quickly dissolves into STOP LIKING THINGS I DONT LIKE, YOU CAN'T HAVE IT, I'M TELLING THE IETF.
- zAy0LfpBZLC8mAC 11y ago> 1) It fails safe. Virtually all device misconfigurations result in failure to pass traffic, rather than being passed accidentally. I don't see that, nor that it would even be an advantage. > 2) You get full control of your external signature (at that protocol level). When Comcast and AT&T realize that they can charge for more than a single /128 on their consumer networks we'll see a lot of wailing and gnashing of teeth on /r/technology, and it will be completely inane to those of us that saw the same companies attempt the same BS with NAT detection in the late 90s. How do you prevent people from coming up with stupid ideas by implementing some stupid ideas yourself? Is that a general rule you follow? Wherever companies could conceivably some day screw up some product, you do it for them now? > 3) I would like to be able to implement dual stack in networks that I'm responsible for with as much similarity as possible. Having to reason independently more than needed about how IPv4 and IPv6 behave is needless difficulty. So, you prefer to keep things broken forever if that means that things don't change? > 4) IPv6 allocations today are asininely large. We're going to have 30-45 years of overallocation and then be out again, What's your evidence for that? Seems like a completely baseless claim to me. > and in the interim we'll have a whole host of new braindead protocols in the manner of FTP and VOIP. So, NAT is good because protocols that don't work well with NAT are braindead because they don't work well with NAT? I mean, I see your point if there is any risk that we might run out of addresses, but if we don't, what exactly is braindead about those protocols? > 5) If it's a useful tool, by the user's estimation, why can't I have it? You obviously _can_ have it. Just as you _can_ cut your head off if you think that's useful to you. But all things considered, do the advantages actually outweigh the disadvantages.
- NetStrikeForce 11y agoI like NAT, too; but just because I like solving the problems it creates. It gets especially funny when you're overloading the public IP address with a one-to-many ratio with internal IP address for outgoing traffic and then you add PAT for incoming traffic. It gets even better when you're only using one IP address for that one-to-many NAT (and it usually is the firewall's external interface IP address because, well, we're lazy), all your internal users are requesting the same external and you run out of ephemeral ports without even realizing. I also like when someone architected an application where the server running it has to request different resources from different external sites and, for some weird reason, has to present itself with different IP addresses. Oh the joy. So many NATs and so many scenarios. It is lovely how different vendors come up with all sorts of names and acronyms: NAT, PAT, SNAT, DNAT, DIP, MIP, you name it! If we didn't have NAT we would have to invent it :)